Okta breach leads to questions on disclosure, reliance on thirdCyberScoop·Mar 24, 21:26 UTC · Mar 24, 2022Exploit / PoC in the wild60
Uncover Your Vendor’s Hidden Infrastructure Before it Becomes a ProblemRecorded Future·Jun 30, 00:00 UTC · Jun 30, 2026Exploit / PoC60
BlueVoyant Supply Chain Defense enhancements reduce issues in third-party ecosystemsHelp Net Security·Sep 21, 00:00 UTC · Sep 21, 2023Exploit / PoC60
GrammaTech CodeSentry 3.0 improves software supply chain securityHelp Net Security·Jan 20, 00:00 UTC · Jan 20, 2022Exploit / PoC60
Third-party Facebook apps left people's data publicly exposed, researchers sayCyberScoop·Apr 3, 21:48 UTC · Apr 3, 2019Exploit / PoC in the wild60
Qualys unveils first-party software risk management solutionHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2023Exploit / PoC60
SolarWinds: What the Intelligence Tells UsRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC60
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsThe Hacker News·Jul 31, 11:17 UTC · Jul 31, 2026Exploit / PoC in the wildCVE-2026-66066CVE-2025-24293160
HackerOne rolls out industry framework to support ‘good faith’ AI researchCyberScoop·Jan 20, 20:59 UTC · Jan 20, 2026Exploit / PoC60
Top 10 Takeaways from Predict 2025: Turning Intelligence Into ActionRecorded Future·Oct 21, 00:00 UTC · Oct 21, 2025Exploit / PoC in the wild60
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wildCisco Talos·Dec 10, 19:37 UTC · Dec 10, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
Google aims to improve security of browser engines, third-party Android devices and apps on Google PlayHelp Net Security·Oct 7, 11:57 UTC · Oct 7, 2020Exploit / PoC in the wild60
Source Defense raises $10 million for website supply chain solutionCyberScoop·Sep 26, 14:59 UTC · Sep 26, 2018Exploit / PoC in the wild60
New certification planned for industry information sharing orgsCyberScoop·Nov 1, 14:58 UTC · Nov 1, 2017Exploit / PoC in the wild60
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face BreachThe Hacker News·Aug 1, 05:20 UTC · Aug 1, 2026Exploit / PoC60
CISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflictCyberScoop·May 5, 21:47 UTC · May 5, 2026Exploit / PoC in the wild60
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
Salesloft Drift security incident started with undetected GitHub accessCyberScoop·Sep 8, 22:44 UTC · Sep 8, 2025Exploit / PoC in the wild60
Amazon MOVEit Leaker Claims to Be Ethical HackerInfosecurity Magazine·Nov 13, 10:30 UTC · Nov 13, 2024Exploit / PoC60
U.S. CISA adds ScienceLogic SL1 flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 23, 13:39 UTC · Oct 23, 2024Exploit / PoC in the wildCVE-2024-953760
Week in review: Windows Event Log zero-day, exploited critical Jenkins RCE flawHelp Net Security·Feb 4, 00:00 UTC · Feb 4, 2024Exploit / PoC in the wildCVE-2024-0402CVE-2024-2389760
Week in review: Oracle WebLogic zero-day under attack, a new way to improve network securityHelp Net Security·Apr 28, 00:00 UTC · Apr 28, 2019Exploit / PoC60
This tool allows you to check the code powering Chrome extensionsCyberScoop·Feb 21, 23:11 UTC · Feb 21, 2019Exploit / PoC in the wild60
Report: personal data of more than 14M Verizon customers is exposed in server breachCyberScoop·Jul 12, 15:40 UTC · Jul 12, 2017Exploit / PoC in the wild60
Microsoft uncovers hacking operation aimed at software supply chainCyberScoop·May 5, 20:58 UTC · May 5, 2017Exploit / PoC in the wild60
Nir Goldshlager Hacked PayPal Users Reports SystemSecurity Affairs·May 30, 07:06 UTC · May 30, 2013Exploit / PoC60
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM MemoryThe Hacker News·Aug 6, 11:30 UTC · Aug 6, 2026Exploit / PoC60
Hidden risks in the financial sector's supply chainHelp Net Security·Mar 4, 07:00 UTC · Mar 4, 2026Exploit / PoC in the wild60
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024Help Net Security·Feb 22, 00:00 UTC · Feb 22, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2026-22769CVE-2026-2329+1 CVEs60
HHS burrows into identifying risks to health sector from thirdCyberScoop·Feb 19, 18:15 UTC · Feb 19, 2026Exploit / PoC in the wild60
Week in review: PoC for FortiSIEM flaw released, Rakuten Viber CISO/CTO on messaging risksHelp Net Security·Jan 18, 00:00 UTC · Jan 18, 2026Exploit / PoCCVE-2025-64155CVE-2025-20393160
⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & MoreThe Hacker News·Nov 17, 12:37 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-64446CVE-2025-64740CVE-2025-64741+24 CVEs60
Week in review: WSUS vulnerability exploited to drop Skuld infostealer, PoC for BIND 9 DNS flaw publishedHelp Net Security·Nov 2, 00:00 UTC · Nov 2, 2025Exploit / PoCCVE-2025-2783CVE-2025-40778CVE-2025-59287+1 CVEs160
Salesloft Drift compromised en masse, impacting all thirdCyberScoop·Aug 28, 19:48 UTC · Aug 28, 2025Exploit / PoC in the wild60
Treasury workstations hacked by ChinaCyberScoop·Dec 31, 01:29 UTC · Dec 31, 2024Exploit / PoC in the wild60
New Research Exposes Security Risks in ChatGPT PluginsInfosecurity Magazine·Mar 13, 13:00 UTC · Mar 13, 2024Exploit / PoC60
Sonar's new deep-analysis capability discovers and fixes code security issuesHelp Net Security·Aug 2, 00:00 UTC · Aug 2, 2023Exploit / PoC60
GhostToken Flaw Could Let Attackers Hide Malicious Apps in Google Cloud PlatformThe Hacker News·Apr 22, 05:34 UTC · Apr 22, 2023Exploit / PoC60
Spin Technology introduces a new solution for Microsoft Office 365 customers to identify risky applicationsHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2022Exploit / PoC160
We need an industry-backed, tech-neutral resource to restore trust in voice communicationsHelp Net Security·Apr 1, 00:00 UTC · Apr 1, 2022Exploit / PoC60